All replies saying "REFUSED"

Hi! I've been running pi-hole on an Intel NUC (running Ubuntu 22.04 LTS) for many many years now, with the occasional hiccough, but the benefits far outweigh the niggles.
However, starting about 9 hours ago, all queries are coming up as REFUSED, and I don't know why. I've spent the day uninstalling and reinstalling and frantic duckduckgo'ing, but still no luck. I can just bypass the pi-hole, but obviously I don't want to do that!

Debug Token:

https://tricorder.pi-hole.net/DDYsW1My/

You have either a connectivity problem to the Google DNS server, or (less likely) the server is not responding. These entries from your debug log are pertinent:

*** [ DIAGNOSING ]: Operating system
[✗] Distro:  Ubuntu
[✓] dig return code: 0
[i] dig response: 0

[✓] doubleclick.com is ;; communications error to 8.8.8.8#53: connection refused via a remote, public DNS server (8.8.8.8)

   Feb 25 18:08:25 dnsmasq[27376]: query[A] api.steampowered.com from 192.168.86.1
   Feb 25 18:08:25 dnsmasq[27376]: config error is REFUSED (EDE: network error)
   Feb 25 18:08:25 dnsmasq[27376]: query[A] ext1-dfw1.steamserver.net from 192.168.86.1
   Feb 25 18:08:25 dnsmasq[27376]: config error is REFUSED (EDE: network error)
   ...

To expand on jfb's analysis:

You seem to run a rather complex setup with quite a few additional software running on the same machine as Pi-hole, including some VPN service's client software.

You may want to investigate that latter further:
I notice that your routing table has two entries that seem asscoiated to your VPN connection, but the subnets do not seem to match, which may or may not have an impact on your observation.

Also note that VPN providers commonly apply forceful redirection of DNS traffic to their own DNS servers, which also may or may not affect you here.

Thank you so much for your assistance jfb and Bucking_Horn, and I'm so very sorry for taking almost a fortnight to get back to you, I've only just had a chance to have a look at it.
Turns out it was the VPN. I had been playing around with Mullvad VPN and trying to create two areas: one for most of the machine that didn't need to pass through the VPN, and one for when I go sailing and do want to use the VPN. I got it working okay, but after a month of stability something must have changed that caused everything to be very grumpy. I completely removed the VPN and it all came good.
I plan on setting up a different machine for sailing under the black flag and that one can just bypass the Pi-hole.
Thanks again for all your assistance, I shall continue to be a happy user and vocal advocate for Pi-hole!

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.